NVIDIA and CrowdStrike launch SafeMind, an agentic cybersecurity system built on Nemotron
NVIDIA and CrowdStrike announced SafeMind on September 1, 2026 at CrowdStrike's Fal.Con conference, a new agentic cybersecurity system that pairs CrowdStrike's proprietary security models with NVIDIA's Nemotron open models to automate both attack simulation and defense inside the Falcon platform.
What's new
According to NVIDIA, "New CrowdStrike SafeMind agentic cybersecurity system built with NVIDIA Nemotron open models delivers greater protection and cost savings for cyber defense." SafeMind was built by CrowdStrike's Cyber Superintelligence Lab and runs on a "continuous coevolution loop," where offensive and defensive AI agents repeatedly challenge and improve each other rather than relying on static rule sets.
Two Nemotron models sit at the core of the defensive side:
- Nemotron 3 Ultra orchestrates SafeMind's defensive agent harness.
- Nemotron 3 Super powers a rule-generation sub-agent and serves as the base for CrowdStrike's new Blue Solano model, which the companies say delivers higher accuracy than leading frontier models at 99% lower cost.
SafeMind ships natively inside the Falcon platform. CrowdStrike also detailed Falcon IQ, a system of more than 50 coordinated agents handling automated assessment, prioritization, and remediation across the trillions of daily security events the company processes for its customers.
Context
The launch comes as both companies frame cyber defense as increasingly outmatched by AI-accelerated attacks. NVIDIA and CrowdStrike cited data showing AI-enabled attacks rose 89% over the past year, with the fastest recorded eCrime breakout time — the time from initial compromise to lateral movement — dropping to 27 seconds. That statistic underlines why both companies are positioning SafeMind as a defense-side answer to attackers who have already begun weaponizing frontier-grade AI models for reconnaissance, exploit development, and intrusion.
The deal extends NVIDIA's push to get Nemotron, its open model family aimed at agentic and enterprise workloads, embedded in production security tooling rather than just research benchmarks. For CrowdStrike, it's a bet that a dedicated "coevolution" loop — attacker and defender models trained against each other continuously — can keep pace with adversaries who no longer need to iterate manually.
Why it matters
"We're at an inflection point in cybersecurity," NVIDIA CEO Jensen Huang said at the announcement. "Attacks are now automated. Defense has to be, too." CrowdStrike CEO George Kurtz was more pointed about the motivation: "The real gap that I saw was that the attackers had frontier AI, and the defenders didn't. And that changes now."
The announcement is a concrete signal that the AI arms race in security has moved past chatbot-assisted triage into fully agentic, self-improving systems on both sides of the fight. If SafeMind's cost and accuracy claims hold up in independent testing, it also reinforces Nemotron's case as a viable open-model foundation for high-stakes enterprise deployments — not just a cheaper alternative to closed frontier models, but a specialized one purpose-built for a narrow, adversarial domain.
Corroborating sources
- Blogs.nvidia
https://blogs.nvidia.com/blog/nvidia-crowdstrike-fal-con-2026/
“combines CrowdStrike's purpose-built, beyond frontier-capable models and customized agentic harnesses, with defensive models built on NVIDIA Nemotron, in a continuous coevolution loop”